Privacy
Last updated October 4, 2026
The short version. The OnService app keeps your log on your phone. Nothing about your hours leaves it unless you join a team, and you can pause that or leave at any time. Your notes are never sent to anyone. We do not sell data, show ads, or track you around the web.
Who runs OnService
OnService is run by its developer ("OnService", "we"). Questions about this page or about your data go to the contact address on the home page.
The app
What stays on your phone
The app stores your log in your phone's browser, on your phone: check-in and check-out times, the type of each entry, notes, your call schedule, vacation days, training dates, the note to your future self, and your settings. You do not create an account and the app does not ask for your name.
Because the log lives in your browser, clearing your browser's data for the app, or deleting the app from your home screen on some phones, erases it. Copy it out from Settings, under Export, if you want to keep it.
The one thing every user sends: a program name
The first time you use the app it asks which program you are in. It sends the program's name, your specialty and the app's version number to us, once. Nothing that identifies you or your phone is sent with it. We use it to count how many people use OnService at each program. If you change your program later, the count is corrected.
Team Sharing, if you choose it
If your program uses the OnService dashboard, it may give you a join link or code. Sharing is off until you join. When you join, the app creates a sign-in for your phone that has no email, name or password, and sends these to our database:
- the name you choose to show your team
- your check-in and check-out times, the type of each entry (Hospital, Clinic or Call), and whether it was marked as a night shift or added by hand
- your call schedule and vacation days
- your first and last day of training
- your Bandwidth settings, so the dashboard scores your hours the way your app does
Your notes are not sent. That covers the notes on entries and the note to your future self.
The app sends updates shortly after you check in or out, and a few times a day while it is open. In Settings, under Team Sharing, you can:
- Pause sharing. Nothing new is sent, and your team cannot see your data until you resume.
- Leave the team. The copy of your data in our database is deleted. Your log on your phone is not touched.
Who can see what you share
The people your program has added to its team on the dashboard: the account that owns the team, and the coordinators it has added. They can read what is listed above. They cannot change it, and they cannot see your notes.
The people who run OnService can reach the database in order to keep the service working, fix problems and answer requests. We do not look at an individual's data except for those reasons.
The dashboard
People who sign in to the dashboard give us an email address and a password. The password is stored in scrambled form by our sign-in provider; we cannot read it. We keep the email address, which teams the account owns or coordinates, and whether the account has been approved. We use the email address to sign you in, to send sign-in and password emails, and to write to you about your account.
This website
These public pages do not use cookies, analytics or advertising, and they load nothing from other companies. Like any website, the company that hosts it keeps a short-lived record of requests (such as IP address, time and page) to keep the site running and secure.
Companies that handle data for us
- Supabase runs the database and the sign-in system for Team Sharing and the dashboard.
- Google receives the program count described above (it is kept in a Google spreadsheet), and serves the typefaces used by the app and the dashboard.
- Cloudflare serves the charting code used by the app and the dashboard.
- Our web host and our email service deliver these pages and the sign-in emails.
When your phone or computer contacts any of them it shows its IP address, as with all web traffic. We do not send them anything beyond what this page describes.
What we do not do
- We do not sell or rent data, and we do not share it for advertising.
- We do not show ads.
- We do not give a program anything about a resident who has not joined its team.
We may disclose information if the law requires it.
Keeping and deleting
- Your log on your phone stays until you erase it. Settings has a button that clears everything.
- What you shared with a team stays in our database until you leave the team. Leaving deletes it. If a program closes its team, or its access ends, residents' shared data is no longer visible to it, and we delete it on request.
- Dashboard accounts are deleted when the account holder asks.
- Backups made by our database provider may hold deleted data for a short time before they are overwritten.
- The program count holds no information about individuals, so there is nothing in it to delete for a person.
To ask for a copy of your data or to have it deleted, write to us. If you are a resident, the fastest way to delete everything we hold is to leave the team in the app.
No patient information
OnService is for logging your own working hours. It is not built to hold patient information and must not be used for it. Do not put names, record numbers or anything else about patients in notes or in the name you show your team.
Security
Data travels over encrypted connections. The database enforces who can read what: a resident can reach only their own data, and a coordinator only the teams they have been added to. No system is perfectly secure. If we learn of a breach involving shared data, we will tell the programs affected and post a notice on this site.
Age
OnService is for adults in medical training and the people who run their programs. It is not meant for anyone under 18.
Changes
If we change what we collect or who can see it, we will update this page and its date. If a change affects data you have already shared, we will say so on this page before it takes effect.